Interesting write up from a 16 year old that discovered a major cross-site scripting vulnerability impacting companies including X and Discord:

The discussion on Hacker News helps to explain the impact.